Launch Week Day 1: Announcing Security Design Review
HIGH 8.1 npm

Server-side request forgery in Ghost CMS

GHSA-q4h8-7qff-gh6c · BIT-ghost-2020-8134 · CVE-2020-8134

Published · Modified

Description

Server-side request forgery (SSRF) vulnerability in Ghost CMS < 3.10.0 allows an attacker to scan local or external network or otherwise interact with internal systems.

Ready to move

Start Securing

Free, no credit card | First findings in minutes